Why the message is deliberately vague
A server that distinguishes “mailbox unknown” from “mailbox exists but will not accept” tells attackers which addresses of a domain are real. Microsoft avoids that and answers both cases with the same line. So the cause is not in the message — it has to be inferred.
The four realistic causes
- The domain belongs to a tenant, but the address belongs to no mailbox. The most common case. The domain is verified in Microsoft 365, the recipient simply does not exist there — not even as an alias.
- Directory Based Edge Blocking. The tenant rejects anything at the perimeter that is not in the directory. Freshly created mailboxes are only reachable after directory sync; until then the address does not exist for the outside world.
- A mail flow rule or a block list. The tenant is deliberately blocking your sender domain or your IP. Then it is not the recipient's fault but yours — the message just does not say so.
- The domain is registered in the wrong tenant. This happens after acquisitions and with test environments: two tenants claim the same domain and the MX points at the one where the mailboxes are not.
Narrowing it down from outside
- Test another address on the same domain. If a known, certainly existing address gets through, the original address is the problem — not you. If that one is rejected too, it points at a block against your domain or IP.
- Send from a different sender domain. If a freemail account gets through while your own domain fails, you have the answer: it is a rule against you.
- Check the MX. If the MX ends in
mail.protection.outlook.com, Exchange Online really is responsible. If it points elsewhere, the message comes from an upstream filter and reads differently.
What you can do — and what you cannot
If it is the recipient, only contact through another channel helps; a foreign tenant cannot be changed from outside. If it is a block against you, the route out is almost always authentication: clean SPF, DKIM and DMARC, a PTR record for the sending IP, a HELO name that matches that IP. A tenant that blocks senders wholesale rarely does so against a domain that fully identifies itself.
The related message 550 5.1.1 states openly that the mailbox is unknown — servers outside Microsoft 365 usually answer that way.